GHub AI
Built by
Closed beta

GDPR Article 28 terms for business use

Data Processing Addendum

Processor terms that apply when an organization uses GHub AI to process personal data on its behalf.

Effective
2026-08-31
Version
2026-08-31
Provider
PROGOS Kft.

Legal documents

Privacy PolicyTerms of ServiceCookie PolicyData Processing Addendum
PROGOS Számítástechnikai Szolgáltató és Kereskedelmi Korlátolt Felelősségű Társaság
1121 Budapest, Ordas köz 2., Hungary
Company no. 01-09-718243
Tax no. 13090166-2-43
info@progos.hu

How this DPA becomes binding

This Data Processing Addendum (“DPA”) forms part of the GHub AI Terms between PROGOS Kft. (“Processor”) and the organization accepting those Terms (“Controller”) where PROGOS processes personal data on the Controller’s behalf. If you require a countersigned copy, additional documented instructions, or a transfer assessment, contact info@progos.hu before using the beta with regulated or sensitive workloads.

1. Roles and scope

The Controller determines which accounts, data and commands are used. PROGOS acts as processor for Workspace content and related account configuration processed to perform those commands. PROGOS remains an independent controller for its own account administration, security, legal compliance and opt-in public-site analytics as described in the Privacy Policy.

“Personal Data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings in the GDPR. This DPA prevails over conflicting Terms only for processing governed by it.

2. Documented instructions

PROGOS processes Personal Data only on documented instructions: the Terms, this DPA, product configuration, scopes the Controller grants, and tool commands issued through an authorized client. PROGOS will inform the Controller if an instruction appears to infringe data-protection law, and may pause it. If law requires processing beyond instructions, PROGOS will notify the Controller before processing unless law prohibits notice.

3. Details of processing

Subject matterProviding a multi-account Gmail, Calendar and Tasks connector and related authentication, routing, security and support.
DurationFor the Service relationship and until deletion or return under section 10, with short technical retention described in Annex I.
Nature and purposeRetrieve, transmit, format, create or update supported Workspace items on the Controller’s instruction; authenticate users; maintain authorized connections; secure and diagnose service operation.
Data subjectsAuthorized users; email senders, recipients and contacts; meeting participants; task/event subjects; and other people whose data appears in connected Workspace accounts.
Data typesIdentifiers, email addresses and headers, message content, calendar and task data, user commands, account configuration, authorization credentials, and shape-only operational metadata.
Special categoriesNot intentionally required, but may appear in Workspace content selected by the Controller. The Controller must not use the closed beta for special-category or criminal-offence data unless it has established a lawful basis, safeguards and written suitability agreement with PROGOS.

4. Confidentiality and personnel

PROGOS ensures that people authorized to process Personal Data are bound by confidentiality and receive access only where needed for operation, security or support. Access is reviewed and removed when no longer required.

5. Security

PROGOS implements the measures in Annex II, taking account of the state of the art, costs, scope and risk. The Controller is responsible for securing its Google and client accounts, limiting scopes and users, reviewing consequential writes, and not using the beta where its risk assessment requires controls the beta does not yet provide.

6. Subprocessors

The Controller gives general authorization for the subprocessors in Annex III. PROGOS will post or otherwise provide notice of an intended material addition or replacement and allow a reasonable objection based on substantiated data-protection grounds. The parties will seek a practical resolution; if none is available, the Controller may stop the affected use. PROGOS imposes materially equivalent data-protection duties on subprocessors and remains responsible for their performance to the extent required by GDPR Article 28.

A connector client independently selected and contracted by the Controller (for example Claude/Anthropic) is not a PROGOS subprocessor merely because the Controller instructs GHub AI to send a tool result there. The Controller is responsible for authorizing and governing that recipient.

7. International transfers

Where PROGOS transfers Controller Personal Data outside the EEA without an adequacy decision, the applicable EU Standard Contractual Clauses are incorporated as the transfer mechanism, using Module Two (controller to processor) where applicable, together with supplementary measures in Annex II. The parties will provide information reasonably needed for a transfer-risk assessment.

8. Data-subject requests and assistance

Taking account of the processing, PROGOS will reasonably assist the Controller with data-subject rights, DPIAs, prior consultations and compliance information. If PROGOS receives a request relating to Controller data, it will direct the person to the Controller unless authorized to respond. The Controller remains responsible for the response and lawful instructions. Disproportionate bespoke work may require an agreed fee; ordinary self-service deletion is included.

9. Personal data breaches

PROGOS will notify the Controller without undue delay after becoming aware of a Personal Data breach affecting Controller data, and provide available information about its nature, likely consequences, affected data and subjects, and mitigation. Notification is not an admission of fault. The Controller decides whether its authority or data subjects must be notified.

10. Return and deletion

At the Controller’s choice, the dashboard can disconnect individual Google identities or delete the GHub AI profile. At termination, PROGOS deletes or returns Controller Personal Data unless Union or Member State law requires retention. Deletion immediately blocks ordinary profile use. If local account, pending-grant or Secret Manager cleanup is interrupted, the blocked profile fields, account configuration and credentials remain only as needed for automatic idempotent retry. After local account and token removal, the durable job retains only the profile identifier, legal acceptance and cleanup state until Firebase session revocation and Auth-user deletion are verified. Both phases retry automatically across service revisions. A minimal profile deletion tombstone then remains for up to one hour, and a one-way-hashed OAuth revocation marker remains through the configured connector-token lifetime plus a one-hour buffer, solely to stop concurrent requests or old tokens from recreating access; Firestore TTL then removes them. Workspace content is not persistently stored by the application. Backups and other provider TTL cleanup may take their normal secure expiry period; during that period data remains protected and unavailable for ordinary use.

11. Information and audits

PROGOS will make information reasonably necessary to demonstrate Article 28 compliance available. No more than once annually, unless required by an authority or incident, the Controller may request a remote audit with at least 30 days’ notice. Audits must protect other customers, security and confidential information, use independent qualified auditors, and avoid service disruption. Existing reports and answers should be used before intrusive testing. Each party bears its costs unless material non-compliance is found.

Annex I — Retention instructions

  • Workspace content: transient for the tool request; no application content store.
  • Connected-account configuration and refresh token: until disconnect or profile deletion.
  • Shape-only telemetry and intentionally submitted feature reports: 90 days.
  • Cloud service logs: 30 days in the production default log bucket.
  • Session: up to 14 days; connector access tokens: configured lifetime, currently 30 days; pending authorization artifacts: logically available for 60 seconds to 10 minutes depending on purpose. Unsaved Google refresh tokens use isolated Secret Manager secrets and shared Firestore cleanup records so scaling or a revision change cannot orphan the revocation handle.
  • Saved-account secret provisioning uses a token-free Firestore reservation (pseudonymous user id, slug and secret reference): normally removed atomically at commit, bounded to 2 minutes for provisioning and 5 minutes for commit recovery, but retained after a failed remote deletion only until verified cleanup succeeds.
  • Deletion recovery blocks ordinary profile use and durably retries interrupted local account/token cleanup; once local cleanup succeeds, it retains only the profile identifier, legal acceptance and deletion state until idempotent session/Auth-user cleanup is verified.
  • Deletion barriers: minimal profile tombstone up to 1 hour; one-way-hashed OAuth revocation marker through the configured connector-token lifetime plus a one-hour buffer (currently up to 30 days + 1 hour).

Annex II — Technical and organizational measures

  • TLS in transit and provider-managed encryption at rest.
  • Google refresh tokens isolated in a dedicated Secret Manager namespace; connector access tokens stored only as SHA-256 hashes.
  • Firebase session verification with revocation checks; OAuth 2.1 authorization code flow with PKCE, single-use codes, redirect allowlists and short expiries.
  • Per-user Firestore paths, authorization boundaries and deletion tombstones that block delayed credential writes; no account secrets serialized to the browser.
  • Least-privilege runtime identity, dataset-scoped access, controlled deployment and dependency checks.
  • Scope checks before write tools, explicit per-account escalation, and no permanent-delete tool.
  • Shape-only telemetry schema, 90-day BigQuery partition expiry, and 30-day Cloud Logging retention.
  • Self-service token revocation, account disconnect, session revocation and profile deletion.
  • Incident investigation and notification procedure proportionate to the closed beta.

Annex III — Authorized subprocessors

ProviderService and dataLocation/transfer
Google Cloud / Firebase group contracting entity and published subprocessorsHosting, Cloud Run compute, Firebase Authentication, Firestore configuration, Secret Manager credentials, BigQuery telemetry, Cloud Logging and supporting infrastructure.Primary production configuration in the EU (europe-west1 where supported); global support/operations subject to Google’s data processing terms, SCCs and published locations.
Google Workspace APIsSource/destination selected by the Controller for Gmail, Calendar and Tasks requests.Under the Controller’s Google relationship and Google’s applicable regional/transfer terms.

Contact for this DPA: info@progos.hu. Provider: PROGOS Számítástechnikai Szolgáltató és Kereskedelmi Korlátolt Felelősségű Társaság, 1121 Budapest, Ordas köz 2., Hungary, company number 01-09-718243.

PROGOS Kft. · 1121 Budapest, Ordas köz 2., Hungary

PrivacyTermsCookiesDPA

Your choice

Cookies, without the fog.

Essential storage keeps your secure session and remembers this choice. With your permission, Google Analytics also measures visits. Analytics stays off unless you choose it. Read the Cookie Policy.